Privacy
Privacy for Coffre.
Coffre's promise is narrow and testable: the server can operate your account and billing, but it cannot read your vault plaintext.
Marketing site
- No cookies.
- No analytics beacon, tracking pixel, or third-party font/script.
- One
localStoragekey,coffre-theme, for light/dark mode. - Server access logs are used for operations and abuse diagnosis.
Hosted app account data
Hosted Coffre stores account email, device records, passkey public credentials, Apple identity links when you choose to link them, sessions, encrypted vault operation logs, encrypted context metadata, push-token registrations, and billing entitlement rows.
What the server cannot read
TOTP seeds, generated codes, generic secret values, item names, issuers, accounts, context names, master passwords, recovery keys, and vault decryption keys stay client-side or encrypted. The server stores ciphertext and sync metadata only.
Hosted billing metadata
The free hosted plan allows 10 TOTP tokens and no generic secrets.
To enforce that without decrypting your vault, hosted clients attach
an item_type value of totp
or secret to item-scoped sync operations. The
server can count item categories. It still cannot read the encrypted
item contents.
Payment providers
Web subscriptions use Mollie checkout. Renewal is managed in Coffre. Coffre stores the provider name, customer id, subscription id, tier, payment identifiers, and current billing period end. Coffre sends the account email to Mollie to create a billing customer. Card details stay with Mollie. Apple and Google purchase verification stores the same account-level entitlement metadata after validating the native purchase with the provider.
If you reach out via hello@coffre.app or security@coffre.app, we keep your message as long as it's useful to answer you.
Self-hosting
If you self-host Coffre, your chosen operator controls server logs, database retention, backups, TLS termination, and any payment or access policy they add around their instance. The AGPL software ships with hosted billing disabled by default.